ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
Spam Call Prevention

What is a stir shaken certificate?

Back to InsightsWhat is a stir shaken certificate?

What is a stir shaken certificate?

Key Facts

Understanding STIR/SHAKEN: How Caller ID Authentication Works

Understanding how caller ID authentication works starts with recognizing the growing problem of spoofed calls that erode trust in phone communications. STIR/SHAKEN addresses this by using digital certificates to verify that a calling number legitimately belongs to the entity placing the call, forming a critical foundation for combating illegal robocalls and spoofing attempts.

The framework operates through a three-level attestation model where originating providers assign a trust level based on their relationship with the caller. Full Attestation (A) indicates the provider knows the customer and verifies they are authorized to use the calling number. Partial Attestation (B) applies when the customer is known but the number cannot be verified. Gateway Attestation (C) is used for calls where the customer or number is unknown, such as those entering the network from international gateways or unverified sources. These levels help terminating carriers assess trust but do not guarantee call approval, as carriers may still apply additional screening based on call analytics.

At the technical core, STIR/SHAKEN relies on public key cryptography where a SHAKEN certificate issued by an authorized Certificate Authority enables the originating provider to digitally sign calls. The STIR header includes a JSON Web Token containing the calling and called numbers along with the attestation level, encrypted with the provider's private key. Upon receipt, the terminating carrier attempts to decrypt this token using the provider's public key; successful decryption confirms the calling number has not been spoofed and the attestation level is valid, while failure indicates potential tampering or lack of authentication.

This authentication process is now mandatory under FCC rules, with full implementation required for all carriers and voice service providers by June 30, 2023, and ongoing enforcement in subsequent years. Despite this mandate, coverage remains limited—only 33.9% of calls were signed at termination in April 2024, a figure TransNexus attributes largely to widespread non-IP interconnections across the telephone network that hinder end-to-end signing. Among signed calls, A-level attestation represented 28.0% in April 2024, up from 26.5% in March, though concerns persist about illegitimate A-level attestations being issued by some providers.

For businesses like CallMyLeads, STIR/SHAKEN provides a valuable signal in lead verification by confirming caller ID authenticity, which enhances trust in inbound communications. However, it is important to recognize that authentication does not equate to spam or scam detection—verified calls can still be unwanted or fraudulent, as STIR/SHAKEN validates identity but not intent. This distinction underscores the need for layered verification approaches that combine caller ID authentication with additional screening tools to effectively assess lead quality and protect against spoofing-related risks.

Why STIR/SHAKEN Matters for Lead Verification and Spam Prevention

For businesses relying on lead response, caller ID trust is foundational to effective verification. STIR/SHAKEN provides cryptographic assurance that a calling number hasn't been spoofed, allowing services like CallMyLeads to establish baseline authenticity before assessing lead intent. This identity verification layer is especially valuable when combined with AI-driven qualification, as it reduces noise from obviously fraudulent sources while preserving focus on genuine opportunities.

A-level attestation—indicating the originating provider knows both the customer and their authorized use of the number—signals higher lead quality in practice. As of April 2024, 28.0% of signed calls carried Full Attestation (A), up from 26.5% in March, reflecting gradual but meaningful adoption of stronger identity verification. However, TransNexus warns that illegitimate A-level attestations persist among some providers, underscoring that attestation alone cannot confirm call legitimacy or intent.

STIR/SHAKEN authenticates identity but does not evaluate whether a call is wanted, spam, or fraudulent—a critical distinction for lead verification systems. Even authenticated calls can be mislabeled by third-party analytics due to call reputation algorithms, not STIR/SHAKEN failure. Therefore, businesses must pair attestation data with independent spam screening and intent analysis to avoid blocking legitimate leads or accepting risky ones. This layered approach ensures identity verification enhances, rather than replaces, comprehensive lead quality assessment.

  • Prioritize A-level attested leads as stronger identity signals
  • Apply additional scrutiny to C-level calls from unverified sources
  • Maintain robust spam screening independent of attestation
With STIR/SHAKEN coverage still limited to 33.9% of calls signed at termination due to widespread non-IP interconnections, absence of attestation often reflects network architecture rather than caller illegitimacy. CallMyLeads integrates attestation levels as one input among many in its verification workflow, using A-level signals to boost confidence while relying on AI screening to assess true lead value and intent. This balanced approach ensures spam prevention doesn't compromise access to genuine opportunities.

How CallMyLeads Uses STIR/SHAKEN in Its Compliance and Lead Process

Caller ID authentication only tells you who's calling — it doesn't tell you whether the call is worth answering. That distinction sits at the heart of how CallMyLeads handles every inbound call, combining STIR/SHAKEN trust signals with its own screening so real leads get fast responses and junk never reaches your team.

Here's the important nuance: STIR/SHAKEN authenticates caller identity, not intent. A signed call with a valid certificate proves the number wasn't spoofed, but it can still be an unwanted robocall. That's why attestation levels work best as one input among many, not a verdict on their own.

CallMyLeads treats attestation data exactly that way — as a signal feeding into its lead qualification and scoring, never the final word:

  • Full Attestation (A) — known caller, known number — carries the most weight in scoring, since the originating provider verified both identity and authorization.
  • Partial Attestation (B) — known caller, unverified number — gets moderate trust and standard screening.
  • Gateway Attestation (C) — unknown caller or number — triggers extra scrutiny before anyone spends time on the call.

One caution tempers this approach: TransNexus analysis found evidence that some providers issue "illegitimate A-level attestations," so a high attestation score alone never overrides other spam indicators. And with only 33.9% of calls signed at termination as of April 2024 — largely due to non-IP interconnections — an unsigned call may simply reflect network architecture, not a scammer. Absence of a signature is treated as neutral, not suspicious.

On the outbound side, compliance follows the FCC's Call Authentication Trust Anchor rule, effective September 18, 2025. That rule allows providers to use third parties for the technical act of signing calls, but only if the provider keeps control of attestation decisions and signs with its own certificate — never the third party's. The FCC was blunt: signing traffic through a third party without meeting these requirements violates caller ID authentication rules.

The practical payoff is simple. Screened spam and robocalls never waste team time — and on metered plans, they're never billed. Real leads, whatever their attestation level, get a response in seconds, around the clock.

Want leads answered before interest fades? CallMyLeads responds to every new lead in under 10 seconds, 24/7/365 — book a free 15-minute scoping call to see how it fits your business.

Frequently Asked Questions

What is a STIR/SHAKEN certificate and what does it actually verify?
A STIR/SHAKEN certificate is a digital certificate issued by an authorized Certificate Authority that lets a phone provider cryptographically sign calls, proving the caller ID number belongs to the caller and they're authorized to use it. It verifies identity only — not whether the call is wanted, spam, or a scam. The signing happens via a JSON Web Token in the SIP INVITE that the receiving carrier decrypts with the provider's public key, and the technology ensures the calling number is accurate and has not been spoofed.
What do the A, B, and C attestation levels mean?
Full Attestation (A) means the provider knows the customer and verified they're authorized to use the calling number; Partial Attestation (B) means the customer is known but the number isn't verified; Gateway Attestation (C) means the caller or number is unknown, like calls entering from international gateways. These levels help terminating carriers assess trust but don't guarantee a call is approved — carriers can still flag or block calls regardless of attestation. CallMyLeads weights A-level calls most heavily in lead scoring, applies standard screening to B-level, and gives C-level calls extra scrutiny.
If a call is STIR/SHAKEN verified, does that mean it's not spam?
No — that's the most common misconception. STIR/SHAKEN only confirms the caller's identity hasn't been spoofed; it cannot assess the intent of the call, so a fully authenticated call can still be an unwanted robocall. As Numeracle explains, spam labeling comes from third-party call analytics at the carrier level, not from STIR/SHAKEN itself. That's why CallMyLeads pairs attestation data with independent spam screening and AI intent analysis.
Is STIR/SHAKEN required by law, and since when?
Yes — the FCC mandated it in phases: large carriers (over 10 million subscribers) by June 30, 2021, carriers with 100K–10M subscribers by June 30, 2022, and all remaining carriers and voice service providers by June 30, 2023, with ongoing enforcement since. Per the FCC's call authentication rules, the obligation now covers voice service providers, gateway providers, and intermediate providers. A newer FCC rule, the Call Authentication Trust Anchor, took effect September 18, 2025 and governs third-party signing arrangements.
Why do so many calls still show up without STIR/SHAKEN verification?
Coverage is still limited — only 33.9% of calls were signed at termination as of April 2024, which TransNexus attributes to widespread non-IP interconnections across the telephone network that block end-to-end signing. So an unsigned call often reflects network architecture, not a scammer. CallMyLeads treats a missing signature as neutral rather than suspicious for exactly this reason.
Can I trust a call with Full Attestation (A-level)?
Mostly, but not blindly. A-level means the provider verified both the caller and their authorized use of the number, and it carried 28.0% of signed calls in April 2024, up from 26.5% in March. However, TransNexus reports ongoing evidence of illegitimate A-level attestations from some providers, so a high attestation score should never override other spam indicators. Layered screening — identity verification plus intent analysis — is the safest approach.

Why Caller ID Trust Is Just the First Step

STIR/SHAKEN provides essential caller ID authentication, helping businesses verify that a number hasn’t been spoofed—but it doesn’t tell you whether a call is worth answering. As we’ve seen, even A-level attested calls can be unwanted, and with only 33.9% of calls signed at termination in April 2024, absence of attestation often reflects network limitations rather than fraud risk. For businesses relying on lead response, the real value comes from layering this identity signal with smarter screening: prioritizing A-level attested leads as stronger trust indicators while applying AI-driven qualification to assess intent and filter out spam. That’s how CallMyLeads ensures real leads get answered in seconds, around the clock, without wasting time on junk. Want to see how fast lead response can work for your business? Book a free 15-minute scoping call to learn how it fits your workflow.

Build My Lead Response Plan

Get lead response tips that actually work